Enables the virtual de-fragmentation of IPv4 and IPv6 packets. This parameter is required for optimal firewall functionality and is enabled by default.

Supported in the following platforms:

  • Access Points — AP505i, AP510i/e, AP560i/h
  • Service Platforms — NX5500, NX7500, NX9500, NX9600, VX9000


virtual-defragmentation {maximum-defragmentation-per-host <1-16384>|
maximum-fragments-per-datagram <2-8129>|minimum-first-fragment-length <8-1500>|timeout <1-60>}


maximum- defragmentation-per-host <1-16384>

Optional. Configures the maximum number of active de-fragmentations allowed per host before it is dropped (applicable to IPv4 and IPV6 packets)
  • <1-16384> – Sets a value from 1 - 16384. The default is 8.

maximum-fragments- per-datagram <2-8129>

Optional. Configures the maximum number of fragments allowed in a datagram before it is dropped (applicable to IPv4 and IPV6 packets)
  • <2-8129> – Sets a value from 2 - 8129. The default is 140.

minimum-first- fragment- length <8-1500>

Optional. Defines the minimum length required for the first fragment (applicable to IPv4 and IPV6 packets)
  • <8-1500> – Sets a value from 8 - 1500 bytes. The default is 8 bytes.

timeout <1-60> Optional. Configures a virtual de-fragmentation timeout, in seconds, applicable to both IPv4 and IPv6 packets
  • <1-60> – Specify a value from 1 - 60 seconds. The default is 1 second.


nx9500-6C8809(config-fw-policy-testFW)#virtual-defragmentation maximum-fragments-per-datagram 10
nx9500-6C8809(config-fw-policy-testFW)#virtual-defragmentation minimum-first-fragment-length 100
nx9500-6C8809(config-fw-policy-testFW)#show context include-factory | include virtual-defragmentation
 virtual-defragmentation minimum-first-fragment-length 100
 virtual-defragmentation maximum-fragments-per-datagram 10
 virtual-defragmentation maximum-defragmentation-per-host 8
 virtual-defragmentation timeout 1

Related Commands 

no Resets values or disables virtual d-efragmentation settings